Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Magic Quotes Oct 11 2006 03:16PM
Matt Fisher (mfisher spidynamics com)


The Santy worm used a simple double-encoded single tick to bypass Magic Quotes. The real problem was the code: it then urldecoded the single-encoded tick at that point, but framework tricks like Magic Quotes are not the "end-all be-all" defense by any means. In fact, Magic Quotes was built out o...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus